Home Blog Page 364

Gentoo reveals reasons for GitHub breach

Gentoo GitHub

Earlier this week, the officials from Gentoo Linux, a Linux distribution, revealed that hackers managed to break into its GitHub account with infected code to manipulate its software and webpages. The officials instructed its users to not fetch anything from Gentoo via GitHub until the things are sorted out.

“Today, 28 June, at approximately 20:20 UTC unknown individuals have gained control of the Github Gentoo organization and modified the content of repositories as well as pages there,” Gentoo dev Alec Warner said in a bulletin. “We are still working to determine the exact extent and to regain control of the organization and its repositories. All Gentoo code hosted on GitHub should for the moment be considered compromised.”

The Gentoo’s security team responded quickly to the incident by sending the misuse notification within 30 minutes of the attack. “The Gentoo GitHub was frozen 70 minutes after the malicious actor gained access, with the Gentoo Infrastructure team identifying the entry point and removing all access for that account from ‘primary Gentoo properties’ as a pre-emptive security measure shortly thereafter,” the incident report stated.

The developers of Gentoo Linux released a distro’s wiki page describing the incident. It unveiled three possible novice mistakes: a weak password, no two-factor authentication and its weak strategies that led to the hack.

The wiki page also stated that the project got lucky. “The attack was loud; removing all developers caused everyone to get emailed. Given the credential taken, its likely a quieter attack would have provided a longer opportunity window.” the wiki revealed.

The code sharing site, Github faced the similar issue when a Chinese drone maker Da-Jiang Innovations (DJI) landed itself into a cybersecurity row over a bug bounty issue. On November 21, 2017, Kevin Finisterre, an independent security researcher, claimed that he found a private key publicly posted on code sharing site Github, after which he was able to access confidential and sensitive customer information and saw “unencrypted flight logs, passports, drivers’ licenses and identification cards.”

Most feds bring own devices to work without agency approval: Report

BYODs

Government Business Council, a research arm of Nextgov, conducted a survey of 165 government employees working in the United States federal and military agencies where it was found that most employees bring their own device to work without the agency approval.

“Among active duty military and Defense Department civilian employees, 43 percent said they use an agency-provided mobile device to conduct government work. On the civilian side, 59 percent said they use agency devices for work,” the report on Nextgov suggest.

“Some of the basic tenets of network cybersecurity is to know who and what is riding on your network,” said Chris Cummiskey, former Homeland Security acting undersecretary and chief acquisition officer, now a senior fellow at George Washington University’s Center for Cyber and Homeland Security in the report. “While ease of connecting personal devices to the network is convenient for employees, it poses a security challenge for IT professionals in identifying and blocking malicious activity that may exist at the endpoint.”

Nearly one-third of the employees do the office related works on the personal devices, but here 94 percent of the Defense employees stated that their personal devices were not approved by the agency, while 64 percent of civilian agency employees said the same about their devices.

And furthermore, it was not like the employees did not understand the gravity of the issue. In fact, nearly 51 percent felt that security is more important than productivity, while 25 percent said vice versa. Another peculiar thing about the survey was that more than half the respondents felt “the agency’s device policy introduces more security risk than is necessary.”

“When you use a computer or smartphone for both work and personal activity, you have added significant risk your personal activity introduces malware that can access your business data and networks,” said Chuck Brooks, the first legislative director for Homeland Security’s Science and Technology Directorate, currently at General Dynamics Mission Systems serving as principal market growth strategist for cybersecurity and emerging technologies. “Many successful attacks aimed at both government and industry have come through phishing and spear-phishing that expanded into cross-contamination of device networks.”

Infosec Superwoman: Lata Bavisi

Lata Bavisi

Over a span of 20 years, Lata Bavisi has had a very interesting career with several industries across the globe. She has been on the board of directors of EC-Council, one of the world’s largest information security certification body, for the last 15 years. However, her love for academia drove her toward cybersecurity education, and she played a pivotal role in establishing EC-Council University as one of the most prominent online cybersecurity education institutes across the globe.

As the President of the University, she has been instrumental in implementing cyber security knowledge into academe, with an aim to achieve practical results in the “real world”. In a conversation with CISO MAG, Lata discusses importance of cybersecurity education, gender diversity in the domain, and much more.

Considering the growing importance of a cyber secure world, what according to you should educational institutions do to motivate more people to take up cybersecurity programs and courses?

Increasing awareness is where I would start from. Today, a cybersecurity profession is still something students think twice about simply because of the lack of cybersecurity education right from inception. Academic curriculum at schools today do not exhibit the need to be cyber safe with the same amount of conviction they have whilst teaching math and science despite the computer being the platform being used to teach those subjects.

We cannot run away from the fact that today technology and the human race are so intertwined that it is incumbent for the young and old to be cyber safe at all times. This then leads to the next question – if technology is part of our daily being then why is cybersecurity education not something that is as appealing as many of the generic professions which have always been around? What about the fact that today there is a serious supply concern for cybersecurity professionals? According to a Capgemini report that came out a couple of months ago, cybersecurity skills hold the highest digital skills gap of 25%.

Hence, awareness at the national, corporate and individual level is pertinent. Cybersecurity needs to be taught at the foundational levels in schools. Once this is in place we will see self-motivated individuals showing a keen interest in cybersecurity programs.

What makes EC Council University unique?

EC Council University is an accredited institution having received its accreditation from the Distance Education Accrediting Commission (DEAC). DEAC is listed by the U.S. Department of Education as a nationally recognized accrediting agency and a member of the Council For Higher Education Accreditations (CHEA).

There are several things unique about ECCU, the first being we are online. Opting an online platform was so that we could reach out to individuals all over the world and allow them the luxury of attaining a degree from one of the pioneers of cybersecurity education without the need to displace themselves and thereby saving both money and time as they could work and study at the same time. Hence, we go to the students rather than the other way around!

The other unique feature of ECCU is its study model. We understand the need for individuals to have a strong foothold on the knowledge component of the subject matter at hand and, simultaneously, the need to have the practical skills aspect being taken care off during the course of delivery of the program. Hence our programs have these seamlessly fused together allowing students to benefit holistically and be industry ready. The practical aspects are taught through our state of the art virtual labs platform known as ilabs. Ilabs allows students to hone their skills by being presented with real life situations in a restricted zone, example where they would go in and attack or defend themselves as part of their assignments.

Was the decision of going completely online a difficult one? There are not many online universities around, especially in the field of information security.

Yes, it was a difficult decision. This many a times works for and against us as there is always a degree of suspicion on the authenticity of online institutions. This sadly is true when there is a lack of research as to the credentials of such institutions. But, we made convenience of our students and quality of education our top most priority.

Going online was not a decision that was taken overnight. We had thoroughly researched the advantages and disadvantages of a completely online university. We, however, were completely motivated from the multiple advantages of online versus on ground especially in a day and age where technology plays a fundamental part in delivering education. The possibilities of creating an environment and experience as close as possible to a traditional institution is a very costly one but promising one too.

ECCU intends to be foreword thinking and the statics show that online education is growing at a rapid pace year after year. The demand for fast and instant is what an online platform does best. In addition to that, being the academic arm of EC-Council, a trusted name in the cybersecurity education space, gave us confidence to choose this route.

What was the motivation behind your decision to join EC Council University’s Board of Directors and assume a Vice President role and how has the journey been so far?

Graduating as a lawyer and a post graduate Bar degree from the Middle Temple in the UK, was no reason not to venture into business. Despite the very lucrative career I was in, I had always wanted to start a school that could impact the lives of many children to welcome a future that would nurture them into proud individuals and citizens of their family, work place and country. The university received its accreditation after 8 long years in 2015 and it was then that I decided to live my dream of creating an educational institution that would be niche in its offerings, unique with its delivery and student focused ensuring that at all times we only deliver quality education that students will benefit from and an institution they can feel proud to belong too.

The journey has been a very interesting one with every challenge being an opportunity and every milestone we achieve being a victory. We have over the last 2 and half years enjoyed a double digit growth year after year. We shall be unleashing many new concentration offerings in our master’s degree in July 2018 which should allow our students to enjoy a more pointed career path that could be suited for them. We have also increased the student benefits from Term 3 onwards where all degree programs would have the EC Council certifications embedded within the program with students not only graduating with their respective degrees but also a string of EC Council industry certifications!

All in all I must admit, the journey has been a very exciting one and the excitement carries on!

ECCU also provides financial assistance to its students. Tell us about that.

We at ECCU recognize the need for financial assistance for students for various reasons and we are always committed to assisting such students. There are several ways in which we assist students financially. First, is by allowing students to pay on a monthly basis through our monthly payment plan. We also offer a few scholarships like the Dean’s scholarship, New Mexico Cybersecurity Scholarship, Women’s scholarship and a Veterans scholarship.

Women’s scholarship is an interesting idea, especially at a time when there is a lack of their representation in information security.

According to a study, women only make up to 11 percent of the global cybersecurity workforce. And even here, the 11 percent has been a stagnant figure since 2013. One of the reasons cited by the study was the lack of enough knowledge about the domain. Most young women did not know what the employers are looking for, and if they had the right attributes. Every domain should have gender diversity, as it is very crucial for it to thrive and cybersecurity is no different. We hope women’s scholarships offered by ECCU inspire women to join the cybersecurity field.

What changes have you seen over the last few years in the curiosity of people toward becoming cybersecurity professionals? Has there been a rise or a downfall?

The recent rise in company (both public and private) hacks and compromises of data, ransomware and the whole lot of techniques used by the criminals to compromise  the security of companies and individuals has to a certain extent itself created an atmosphere of awareness that there is a not only a need for cybersecurity professionals but also a glut. Such headline news in all and any media coverage will surely create curiosity amongst viewers on how the country needs to deal with such cybersecurity situations.

The increased enrollments at our university and larger proportion of individuals looking at upskilling themselves through the certification route is proof that there has been a significant increase amongst individuals to either opt out of their current careers and join the cybersecurity community or a strong inclination of younger individuals to select from the start a career in cybersecurity.

A number of students often begin their careers by going for certificates instead of a proper degree. Do you think it is the right approach?

Many individuals often become confused or select the wrong path when getting into a cybersecurity career. Often they believe that certifications alone suffice to getting them onto the track of a full blown cybersecurity career. However, statistics point to the fact that at least 84% of companies require their cybersecurity workforce to have a degree. Certifications should be used as a means to upskill oneself. The reason for the same is quite obvious when looking at the vast number of complaints received from organizations that the cybersecurity professionals do not have the requisite talent required to defend their systems. The degree has both the knowledge and practical component required to ensure the individual is industry ready.  This further ensures the individuals have a secure understanding of the foundations of the subject matter of their study and walk out with the breadth and depth of knowledge that would be required to qualify as a cybersecurity professional.

There are many C-level executives rising to the level of CISOs. How much is cybersecurity certification important to them apart from a career boosting factor?

As I had stated above, certifications should form the basis of upskilling one’s self. Cybersecurity is a fast moving and evolving domain of study and it is pertinent for individuals to remain abreast with the latest techniques deployed when protecting an organization. These are the major advantages of certifications that cannot be ignored. At EC Council University, we offer transfer credits for certifications that were awarded within the 3 year timeframe if not the student needs to ensure that he/she has renewed the certification concerned by sitting for a more current exam.

In order for CISOs to continue to be respected, lead with the requisite knowledge and be armed with the most current information in cybersecurity, there is no doubt that certifications will be the road to take. But again, a CISO must be armed with a cybersecurity degree first. This is where EC Council University is a clear winner as it has bundled within its Masters’ degree offerings, cybersecurity certifications that are part of the course allowing the individual to graduate as a CISO with a string of certifications.

According to you, what are the three main factors that one should look into before selecting the right cybersecurity course and institution for themselves?

With various institutions, colleges and universities offering cybersecurity degrees, it has become a difficult task for individuals to zero in on the right one. Hence in my opinion the first thing one needs to look into is the reputation of the provider in the field of study. Is that where the expertise of the provider lies? Is it an accredited institution? These are important points to tick on your check box as there are so many grey market providers today that collude the mindsets of individuals that are less informed into believing they are receiving premier education and most of the time at prices that could be tempting.

Second would be to consider the value of the education provided. Example, many institutions claim to provide practical knowledge through lab components. However, it is important to ensure that you have adequate knowledge on what those lab components are. In the case of ECCU, we have made huge investments in providing a cyber range of high quality and is cutting edge that gives students a real life case to solve in guided and closed door environments.

Third is the quality of the faculty that delivers the education. This is a key component in education of any sort. We always need good mentors that we can fall back upon when in doubt and someone who can mold us and bring out the best in us. Many online universities today depend heavily on technology and ignore the human factor. At ECCU however, our faculty are full time practitioners who are well informed on the subject matter concerned and practicing it on a daily basis. There can be no better fit to creating the right talent pool when this is the formula.

What would be your advice to a budding information security professional?

Today many individuals consider the job prospects before looking at anything else. However, in my opinion, an individual will be hired and retained by the best if he/she takes the first step in ensuring that they are true to what they learn. Commitment, perseverance and hard work always pay off if the 3 points above were paid attention too. An education is there to form you and your thoughts but what you make out of it is entirely on your shoulders. Good luck to all aspiring cybersecurity professionals in this journey.

Building walls while leaving the doors open

Application Security

Contributed by Chris Roberts, Chief of Adversarial Research and Engineering at LARES Consulting

Let’s start with some simple statistics:

  • Over 80 percent of digital attacks are levied against the application layer.
  • Over 80 percent of current IoT devices on the market have had little-to-no application security testing.
  • In the next two or three years, there will be over 20 billion IoT devices connected to the Internet.

By those simple statistics we now know that somewhere in excess of 16 billion unsecured devices will be connected to the Internet – and this is beyond what we have to deal with today. We are spending billions and billions of dollars a year trying to protect everything, yet we have failed to realize the extent of this tsunami of tech that’s heading our way and being integrated into our homes, lives, offices, families, transportation, and pretty much our entire interaction with the world around us.

What do we do to change things?

Let’s take a look at the history and the future:

Read more

New cybersecurity report states cryptojacking is a rising cyberthreat

Eterbase cryptocurrency Exchange hacked, OpenSea

A recent report from cybersecurity firm WatchGuard Technologies has stated the rising threat of crypto-mining malware highlighting that it might become a dangerous malware attack in coming days. The report anticipated malware attack could be in the list of top 10 cyber attacks by the year-end.

Corey Nachreiner, CTO of WatchGuard Technologies, stated, “Though we only publish this report at the end of each quarter, our Threat Lab team looks at our malware results daily. During early Q2, our daily data shows various ‘Coinminers’ continually appearing on our top 25 list. While it’s too early to say if they will break the top 10 for Q2, we expect them to continue to grow in popularity over the next few quarters.”

The findings of the reports are based on the network of 40,000 threat management applications installed across the world. The report also exposed the nature of cryptojacking and explained how a script forces Linux device to run a Monero miner which weakens the device’s processing power.

During the past year, an astronomical rise in cryptocurrency values triggered a cryptojacking gold rush with cyber criminals attempting to cash in on a volatile market. Detections of coin-miners on endpoint computers increased by 8,500 percent in 2017. India ranks second in Asia-Pacific Japan (APJ) region, ninth globally in terms of crypto mining activities.

Cyber criminals are rapidly adding cryptojacking to their arsenal and creating a highly profitable new revenue stream, as the ransomware market becomes overpriced and overcrowded, according to Symantec’s Internet Security Threat Report (ISTR).

“Cryptojacking is a rising threat to cyber and personal security,” said Tarun Kaura, Director, Enterprise Security Product Management, Asia Pacific and Japan, Symantec. “The massive profit incentive puts people, devices, and organizations at risk of unauthorized coinminers siphoning resources from their systems, further motivating criminals to infiltrate everything from home PCs to giant data centers.”

 

Surge in cryptocurrency crimes caused $761m loss in 2018: Report

Cryptocurrency mining

According to a report from US-based cybersecurity firm CipherTrace, the first six months of this year experienced a huge surge in cryptocurrency exchange thefts.

The report released on Tuesday stated a total of $761 million was stolen from cryptocurrency exchanges in the first half of 2018. The amount already exceeds the whole amount, $266 million, of 2017 by three times. The company also estimated the losses could rise to over 1.5 billion in the current year.

“Stolen cryptocurrencies are three times bigger this year than last year, so the trend is obviously not our friend here,” Dave Jevans, the chief executive officer of CipherTrace and the chairman of the Anti-Phishing Working Group, told in an interview with Reuters.

“The stolen virtual currencies end up being laundered to help criminals hide their true identities and avoid arrest, which has resulted in a three-fold rise in money laundering of cryptocurrencies,” he added.

On June 20, 2018, Bithumb, the world’s sixth-largest and South Korea’s second-largest cryptocurrency exchange, suffered a massive breach after hackers stole 35 billion won ($31 million) from the platform. The exchange immediately halted deposit and withdrawal services from its servers. The company has assured that it will cover all losses so that users will not be affected. Within an hour of information going public, the price of Bitcoin price dropped nearly $200, erasing much of the recovery that the markets had seen over the previous two days.

South Korean cryptocurrency exchange, Coinrail, also suffered similar fate on June 10, 2018, after which the value of bitcoin dipped an all-time low of at $6,790.88, a 10.8 percent slump in a week and a massive dip from its December 2017 peak, where the coins recorded an all-time high of almost $20,000.

Hamas honey traps Israeli soldiers with fake dating apps, succeeds getting negotiable intel

Israeli Soldier

Palestinian Sunni-Islamist fundamentalist organization Hamas has been accused by the Israel army’s intelligence directorate for building fake dating and FIFA World Cup 2018 applications to entice soldiers into downloading malware on to their mobile phones with the intention to gather sensitive information about the military activities around Gaza strip.

According to reports, several Israel Defence Forces (IDF) personnel were contacted through social media to download dating apps like WinkChat and GlanceLove. Hamas also created bogus profiles with the stolen identities of young women, asking to chat on WhatsApp and interact with soldiers and later requesting them to download their Trojan Horse apps on Google Play Store. The applications allowed the creators to know the user’s location, contact list, access the phone’s audio device to tap calls as well as access video camera to monitor activities. The operation targeted Android phone users. “Whatever you can do with your phone, the malicious content can do,” reported The Guardian. Apparently, Hamas could film the activities on Israel Defense Forces bases without the soldier’s knowledge of the hack.

The other bogus app called Golden Cup shared World Cup live scores. It was advertised to advertised to soldiers in Hebrew on Facebook.  It even streamed videos of previous tournaments and listed details of each team. According to the official, “It was actually a very good one.”

But Hamas didn’t stop there. It also used a fitness app to identify the phone numbers of soldiers who went jogging near the Gaza strip. As soon as Hamas had access to these numbers, the soldiers were requested to download the apps.

Fortunately, the attack couldn’t gather its desired intel, as most soldiers who were approached to download the app either refused or reported the incident to their seniors. The number of personnel who downloaded the apps were conceded, though the military said, “less than 100 installed at least one program on their phones.” The IDF unit responsible for identifying the hack called it ‘Operation Broken Heart’, as it failed to honeytrap military personnel. Apparently, both men and women were targeted in the operation by Hamas. On the downside, the fundamentalist front may have gathered information on a number of Israeli bases and the armored vehicles stationed there.

“Perhaps a little suspicion could have saved the soldiers from falling into Hamas’ trap, but what’s really impressive about this attack is the way it exploited the infrastructure provided by giant technology companies,” wrote Oded Yaron a Haaretz Contributor. “Google’s Android system has been criticized for years as less secure than Apple’s iOS, and Google has tried repeatedly to prove that it’s fixing the problem by beefing up its protections. Last year, for instance, it unveiled Google Play Protect — a platform that provides improved protection for users, both on their devices and Google Play, the company’s digital app store.”

Former U.S. Air Force CISO boards Raytheon

Former CISO of United States Air Force, Peter Kim has joined military contracting giant Raytheon as its director of IT security and governance for its subsidiary Raytheon Missile Systems. Within a month after departing from the U.S. Air Force, Kim took the new role. Wanda Jones-Heath, his former deputy, has replaced him.

During his regime at the U.S. Air Force, he was “responsible for the oversight, development and execution of the Air Force cybersecurity program to provide confidentiality, integrity and availability for the information and information systems that support Air Force operations and support activities,” states his bio on the U.S. Air Force website.

He was also entrusted with “ensuring integrated and synchronized strategic employment of cybersecurity with cyber operations to deny freedom of action to adversaries, accomplish Air Force and joint force commanders’ objectives and enable mission assurance of AF Core Missions.”

Kim has spent the last decade at the Pentagon working in cybersecurity. In 2006, he Kim took over as the commander of the 92nd Information Operations Squadron, where he worked with Joint Chiefs of Staff on cyber policy. Kim has also served several roles within the Air Force, from Deputy Director of Cyberspace Operations; Director, Task Force Cyber Secure and Deputy Director, Cyberspace Operations and Warfighting Integration; and Air Force Senior Information Security Officer, Director, Task Force Cyber Secure, and Deputy Director, Cyberspace Operations and Warfighting Integration, Headquarters U.S. Air Force.

He was also instrumental in the development of the Air Force’s first bug bounty program. “We continue to harden our attack surfaces based on findings of the previous challenge and will add lessons learned from this round,” Kim said in February. “This reinforces the work the Air Force is already doing to strengthen cyber defenses and has created meaningful relationships with skilled researchers that will last for years to come.”

Israel-based cybersecurity startup PlainID raises $11million

Israel cybersecurity startup

In its Series A round of funding, PlainID, an Israel-based cybersecurity startup has raised $11 million to accelerate its U.S. sales & marketing operations, customer support, and R&D team. The company announced that the latest investment is directed by Viola Ventures with the participation from Capri Ventures, Springtide Ventures, and iAngels.

Founded in 2015 by Dmitry Tuchinsky, Gal Helemski, and Oren Ohayo Harel, PlainID is specialized in simplified authorization management services giving a clear idea of every authorization in the cloud, mobile, and on-premise applications. The authorization platform allows the business leaders, data governance professionals, and security teams to get a complete control over the entire organization’s authorization process.

“The authorization landscape is changing and understanding who can access what and when becomes a critical question, that requires a good answer,” said Oren Ohayon Harel, CEO and Co-Founder of PlainID. “A simplified authorization platform meets the intricate demands of a growing enterprise by maximizing security and minimizing anxiety.”

“Run-time authorization is becoming more complex in an era of Enterprise automation. Current solutions no longer meet the changing requirements of hybrid IT environments, API collaboration and the introduction of more robotic process automation solutions,” said Omry Ben David, Partner at Viola Ventures. “We believe that externalized fine-grain authorization will become the next large category in IAM, in a similar way to how Okta built the authentication category by externalizing the process and offering a single sign-on solution.”

On addressing on the new move, Marek Jablonsky, Executive Director at Springtide Ventures said, “PlainID provides a new generation tool allowing managers to gain control and flexibility in managing authorization across their organizations while minimizing dependency on IT specialists. Importantly, the solution also addresses regulatory requirements and provides the necessary “peace of mind” to the executives when it comes to auditable robustly process-based IAM. Building on their hands-on experience from their previous roles as IT security executives with large enterprises the founders have managed to develop a largely superior solution with a potential to disrupt and redefine the category.”

Key Australian government agencies fail to implement cybersecurity strategies

An inspection by the Australian National Audit Office (ANAO) has exposed the failure of government organizations to implement cybersecurity requirements.

The ANAO’s fourth report on the cyber resilience of government departments and agencies states that except the Treasury Department both the National Archives and Geoscience Australia failed to implement the top four mandatory cybersecurity strategies instructed by the Australian Signals Directorate (ASD).

“This audit identified relatively low levels of effectiveness of Commonwealth entities in managing cyber risks, with only one of the three audited entities compliant with the Top Four mitigation strategies. None of the three entities had implemented the four non-mandatory strategies in the Essential Eight and were largely at early stages of consideration and implementation. These findings provide further evidence that the implementation of the current framework is not achieving compliance with cybersecurity requirements and needs to be strengthened.” the ANAO said in its report.

The top four mandatory strategies include application whitelisting, application patching, OS patching, and the control of administration rights. Also, there are four non-mandatory but recommended cybersecurity mitigation strategies for all the government bodies. According to ANAO, execution of these four measures has been mandatory since April 2013.

The ANAO also revealed that Geoscience Australia is vulnerable to cyberattacks due its lack of compliance with any of the essential eight cybersecurity guidelines.

“Geoscience Australia was assessed as vulnerable, with a high level of exposure and opportunity for external attacks and internal breaches and unauthorized disclosures of information. Geoscience Australia has traditionally had a culture of scientific independence that it had allowed to override resilience considerations,” the report found.

Agreeing to the ANAO’s recommendations, Geoscience Australia responded to the report stating “Geoscience Australia is committed to improving its security compliance and cyber resilience to a level of appropriate for a government organization that plays a role in providing scientific information and services to industry and the broader community,” the agency said in a statement.

A parliamentary committee has also suggested making it mandatory for government bodies to implement Australian Signal Directorate’s essential eight cybersecurity guidelines to create a positive cyber resilience culture.